Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: T1567.002 test 2 #3057

Merged
merged 2 commits into from
Feb 21, 2025
Merged

Conversation

ryananicholson
Copy link
Contributor

Details:
This atomic test will exfiltrate data from a chosen directory to AWS S3 using rclone. This test will also use Terraform to deploy an S3 bucket for exfil.

Testing:
Performed the test using the following commands:

Invoke-AtomicTest -AtomicTechnique T1567.002 -PathToAtomicsFolder ./atomics -GetPrereqs
image
Invoke-AtomicTest -AtomicTechnique T1567.002 -PathToAtomicsFolder ./atomics
image
Invoke-AtomicTest -AtomicTechnique T1567.002 -PathToAtomicsFolder ./atomics -Cleanup
image

Associated Issues:

No issues corrected with this PR.

@patel-bhavin
Copy link
Collaborator

This is a neat PR @ryananicholson ! Also, to be honest I am really liking this template of using the combination of pwsh and terraform !

@patel-bhavin patel-bhavin merged commit 27c202f into redcanaryco:master Feb 21, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants